From patchwork Sat Aug 8 11:06:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Cong Nguyen X-Patchwork-Id: 2951 Return-Path: X-Original-To: noreply@patchwork.local Delivered-To: noreply@patchwork.local Received: from sto.lore.kernel.org (sto.lore.kernel.org [172.232.135.74]) by mxe881.netcup.net (Postfix) with ESMTPS id 01B961C143D for ; Sat, 8 Aug 2026 13:06:30 +0200 (CEST) Authentication-Results: mxe881; dkim=pass header.d=gmail.com; spf=pass (sender IP is 172.232.135.74) smtp.mailfrom=linux-sunxi+bounces-25077-noreply=patchwork.local@lists.linux.dev smtp.helo=sto.lore.kernel.org Received-SPF: pass (mxe881: domain of lists.linux.dev designates 172.232.135.74 as permitted sender) client-ip=172.232.135.74; envelope-from=linux-sunxi+bounces-25077-noreply=patchwork.local@lists.linux.dev; helo=sto.lore.kernel.org; Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sto.lore.kernel.org (Postfix) with ESMTP id 21C813009F67 for ; Sat, 8 Aug 2026 11:06:29 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 78F1B3C1D44; Sat, 8 Aug 2026 11:06:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="r98i6F0Z" X-Original-To: linux-sunxi@lists.linux.dev Received: from mail-pl1-f175.google.com (mail-pl1-f175.google.com [209.85.214.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E566326CE05 for ; Sat, 8 Aug 2026 11:06:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.175 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786187188; cv=none; b=hhydt/SAwPyWYHt7dd51EfUp7Sp7AdIwUqE5w1rIUilWjrAW4a/kzR0i1zsPM/ixyggqqeL2DQF7HMydSDJjlsCv28Uo9eEUUzdRTYO/fj1kz0rlUb7cT0L34i2xKe7zRyXglX6MYvikoMvt9PGPU2sQvba2+lmfN8M28i83KGk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786187188; c=relaxed/simple; bh=tDsFj4Lh9ROCK1QL6OxCscLJBiWTpO7vMwF1199NUaA=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=WEt+tk6wywrqMwChPCkS0Szc5Te6SDKndKOz6y2Jo00j6PD3DX2jtx48NcwQ/uBDK9j38dLF2jObZBQKcPNaE5lSBnKnvDapUu5aIUwYxGONS/TvqEYgqZuIWlzMYmPAqDyJRsYGxrmvmUc0QInkazp/thjvIeV+OGgLz4tDeoM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=r98i6F0Z; arc=none smtp.client-ip=209.85.214.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pl1-f175.google.com with SMTP id d9443c01a7336-2ceab75934dso4556435ad.2 for ; Sat, 08 Aug 2026 04:06:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786187185; x=1786791985; darn=lists.linux.dev; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hTWsfLJS/81iyczYbFu23mRRJqJRdNk8TSWy7ODIao4=; b=r98i6F0ZlKSSovUxxfPCvXS6qJHARND6bJJB/daTompIXXAbc2t/5ZD7myg6zxbKLv TluQOVFzNYcfcWd7ke0iPkYHKs1tiS3cRxLKB3y+9wsBzMmDv/Xz4SkSWWS+a4qICBl0 yl27qevapfsFyqFwBRZi3BrJWPe1HZAB5Kg5YOD1FOd1SIU9pa1jh94tZQGcyYxwccll b6Bymo7JRvK4CSUAMJcyQ5qaNucek9HvaTMKfAKHC+eHJ7X+n1txXfUFtzD9PINisQCh njHu5y88ehHglaot7ybg83LNdDeLlJiyFTzQjYZdpX0aCsGy+l8ZMISo7SZ09dPdRIqX +R5Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786187185; x=1786791985; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=hTWsfLJS/81iyczYbFu23mRRJqJRdNk8TSWy7ODIao4=; b=bcH1jXd5z3sYqXYd9UJck4AOQYOiqAD/JMckIvDA5g7Br3DkC89Ln51pkjSGBiWCaX lVgghU1XsFqI1eewU0eFL7vNsHYL/eMKEa4tWAeEqrAF3esb5IzuqIJ8bqv7E+9aUB84 GMUxBkZfEnYosmNK32j5NQ4rKexlz2M1JLcikA9DGwuo5mB7JnkYCd5q0t3zaVRT9CJu GV2n7aVJz0Z7/h7A4Svu0RazHUUrt3R3XfweLQfbGcuhzryTxpL5siVCUdKARTov96gh 8b5Avbex/6sijTO08j9CWXgJ/zgznToHz0OpawQJoQiG45Ken782s31aZqUpJQu2wYTq G/fQ== X-Forwarded-Encrypted: i=1; AHgh+RpUKL7cXdLKOo6gyOxa9waONl98gq/l3cSBua7ZieaRrbLDdBxLfiAhVPOyVZq4nQkQWFhW0iEZfGJ45Q==@lists.linux.dev X-Gm-Message-State: AOJu0Yyt3YGAia+xm6E8nHoWWbVqipG1T8hoidSp8oR0+IeFDd/+OQst 7vhCZDpNPSO80drXolQ//1I+0ohzCTZthUNE7JinmUqXR2k+OUauHFxJ X-Gm-Gg: AR+sD11hW9x5n3c4RTubQYFlf1zI8Vvnu4XE+0wOYht05UA4JC8hJCCq/JLbz1XhYj2 yEeyPS6Ul8ZVs8a9xKKNw9Tap7AeqNd9l7LpOHpDrPXMbpfeLATwTIb4yu2lZH9jFtDSsANDlr/ 8THFyOT2fj4QeiGExvKTIHayWnbxyo+jMHFiNY+zgsDGOzDiLo7KmTewUCLawKRjFXEOD0MPQwS l1sAJspOxiT+L5hH0pPWZzQVnfC16XJ4TnIOmMJRoYYrVJ9fSXIDK/oNVYj5IxBvkp9xSn9YpG6 qunmixNe5Q2b3K4YUkRY2J3wF/z50H3cUrxKGl+38NlaOmK+pTpc6E1O5nlZbTyntlmPIleLLP8 z1O3PvLHqf+2aor5mAIDWpC+aQFa/RcAsooBjAuv674pwT6joObdM7fYCziUM8hqP3yFXC8NTH3 oudMMMIS40IiTBYSVAMiuaTphGGn5jWknkdxRo2+hSxs1XWjXak9WFVbn8An5+SqcFGiHjUpOM6 kSlMw== X-Received: by 2002:a17:90b:2dc1:b0:38f:de97:b06 with SMTP id 98e67ed59e1d1-3903c535d79mr33954628a91.5.1786187185202; Sat, 08 Aug 2026 04:06:25 -0700 (PDT) Received: from SGN-LDSENG.tasernet.com ([2405:4800:5cc3:11a:1ac0:4dff:fe8b:4a69]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-141019b4eabsm15243343c88.6.2026.08.08.04.06.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 04:06:24 -0700 (PDT) From: Cong Nguyen To: Maxime Ripard , Mauro Carvalho Chehab , linux-media@vger.kernel.org Cc: Chen-Yu Tsai , Jernej Skrabec , Samuel Holland , Sakari Ailus , linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-kernel@vger.kernel.org, Cong Nguyen , stable@vger.kernel.org Subject: [PATCH v1 1/3] media: sun4i-csi: fix video device and subdev leak in notify_complete() Date: Sat, 8 Aug 2026 18:06:15 +0700 Message-Id: <7804a3c87beefde14e0358fa2a11e63005525890.1786184456.git.congnt264@gmail.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-sunxi@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-MORS-Enabled: yes X-MORS-DOMAIN: patchwork.local X-MORS-HOSTING: hosting172546 X-MORS-USER: hosting172546 X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= sun4i_csi_notify_complete() registers the bridge subdev with v4l2_device_register_subdev() and the video device with sun4i_csi_v4l2_register() (which calls video_register_device()) before it creates the media pad links and registers the subdev nodes. If any of the later steps fail, the error path only unregistered the media device: err_clean_media: media_device_unregister(&csi->mdev); return ret; The already registered video device and bridge subdev were left behind. Because this failure propagates back through v4l2_async_nf_register() and aborts probe, the driver's devm-managed struct sun4i_csi (which embeds the video_device) is freed while /dev/videoX is still registered, so a subsequent open() from userspace dereferences freed memory. Unwind the registrations in reverse order on error, mirroring the teardown in sun4i_csi_remove(): unregister the video device with vb2_video_unregister_device() and the bridge subdev with v4l2_device_unregister_subdev(). Also unwind the intermediate v4l2/media registration steps so every early return leaves no half-registered state. Fixes: 577bbf23b758 ("media: sunxi: Add A10 CSI driver") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4 Signed-off-by: Cong Nguyen --- drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.c b/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.c index e53a07b770b7..a8711336a754 100644 --- a/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.c +++ b/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.c @@ -85,11 +85,11 @@ static int sun4i_csi_notify_complete(struct v4l2_async_notifier *notifier) ret = sun4i_csi_v4l2_register(csi); if (ret < 0) - return ret; + goto err_unregister_subdev; ret = media_device_register(&csi->mdev); if (ret) - return ret; + goto err_unregister_video; /* Create link from subdev to main device */ ret = media_create_pad_link(&subdev->entity, CSI_SUBDEV_SOURCE, @@ -114,6 +114,10 @@ static int sun4i_csi_notify_complete(struct v4l2_async_notifier *notifier) err_clean_media: media_device_unregister(&csi->mdev); +err_unregister_video: + vb2_video_unregister_device(&csi->vdev); +err_unregister_subdev: + v4l2_device_unregister_subdev(subdev); return ret; } From patchwork Sat Aug 8 11:17:09 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Cong Nguyen X-Patchwork-Id: 2952 Return-Path: X-Original-To: noreply@patchwork.local Delivered-To: noreply@patchwork.local Received: from sto.lore.kernel.org (sto.lore.kernel.org [172.232.135.74]) by mxe881.netcup.net (Postfix) with ESMTPS id 784FE1C1930 for ; Sat, 8 Aug 2026 13:17:30 +0200 (CEST) Authentication-Results: mxe881; dkim=pass header.d=gmail.com; spf=pass (sender IP is 172.232.135.74) smtp.mailfrom=linux-sunxi+bounces-25078-noreply=patchwork.local@lists.linux.dev smtp.helo=sto.lore.kernel.org Received-SPF: pass (mxe881: domain of lists.linux.dev designates 172.232.135.74 as permitted sender) client-ip=172.232.135.74; envelope-from=linux-sunxi+bounces-25078-noreply=patchwork.local@lists.linux.dev; helo=sto.lore.kernel.org; Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sto.lore.kernel.org (Postfix) with ESMTP id 1BBD9300F472 for ; Sat, 8 Aug 2026 11:17:25 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 9E4DA3CEBB7; Sat, 8 Aug 2026 11:17:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="BNc3geVA" X-Original-To: linux-sunxi@lists.linux.dev Received: from mail-pg1-f172.google.com (mail-pg1-f172.google.com [209.85.215.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0BAA73CDBB7 for ; Sat, 8 Aug 2026 11:17:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.172 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786187842; cv=none; b=Qhqr7ba8HSbvF2++waRzC8tBUsXXfLLcEvULXOyqCOmjK0jvkmLLqhehSpFcibD6bavjQAt3mPajDhO9BpzeNpQmtIn7aBZxkywPcVoGmLctQveY91PP0+wd4DbapvRPKe7YIy2UMguc2iiRmTm95YNWT8YC6JCKt/VXZTEy8J4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786187842; c=relaxed/simple; bh=/o1udNNLV+FNe1R9p8BzEoEJfIqD9mThtLK2mmEohxQ=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=b/58C2bg5mi5oIUfsKfj7tpGLI/bgvt79Rhe26FCVeWayTQCLS1SdtSNLtY8udGEPsQl6l2g3dW6X1pH93oI8CT5V4vzz02M9ZZvdl+FYCuHYhddOVNqNamOyuzrpKlbhQ8O0sW6ipPMS8Hi1PhQ7b7AhzwsZwJs21TqoW1Ox7Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=BNc3geVA; arc=none smtp.client-ip=209.85.215.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pg1-f172.google.com with SMTP id 41be03b00d2f7-c9c26a5fb98so249179a12.0 for ; Sat, 08 Aug 2026 04:17:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786187840; x=1786792640; darn=lists.linux.dev; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VegdV0CGVtEAsdoGYq2fWs6TLBlXPmk2Egy9/veY9KE=; b=BNc3geVAZg0/uU3Gb4BQXR/Ow72hVYU4XrxIpvsmNNpqn2ecTFPY24jn+ppqaXtxs8 QBCg/FKCSBnwZjR+yLMJft3oBhKSZalOgbFts7OhX0UwoOJip2sJ+d4kfbMTBhpUHZgi nKDMozU1dwC7C4CCoD69mnUemPa5M4mm85IyoDD5mzX/nNLdoUPgo+nsqwTgIwkBLtgO F6+hrYo378/euMHYqIv0bqCQYUkxERrBl6xzvge2rZimm6cJiiCOjCmGcwa7TpunsfMe tmJYBjMl2HNQ/r8PN3d7apc/+apX1tFwTWUFEKIBoglGjulnQlyQkJLOE+P0HfctAObv nx8g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786187840; x=1786792640; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=VegdV0CGVtEAsdoGYq2fWs6TLBlXPmk2Egy9/veY9KE=; b=B/YUg+tgadLcRmNnRitCMc+xkjq0UWWr3iy1snXDle0Tr15EKWMvFYS3ADvQoEkKQ1 uGcBQ193FW6o597ZrKcg1ErjrDtJJREYAsBj+VQEmKcnLFtcc1LhPd5XOqvvPT/m6s9j TcdGX2Z1Nk6lym56/mpI8dYGy2VI3m/vIAitTIDXOXr9fEQ5Kkd+kAAOA0PhSPvgEMeQ YdtUKgLU5uWpQHHocCFmOgjQuE6PrM8SLCSESFK5Cl/ZHTeu9FPao04eBI3K8PK7Q+3m NB9EEkAX8V8HibLpMXvBa3Tcwh1juKIyjdf7/Ufl7LO+Rq19dxdAS6QTRedULkf3JsOA LLMQ== X-Forwarded-Encrypted: i=1; AHgh+Rp4uZhif0A4X6WqJJK12zWYcirI5IFq08JqV6O3hKGNb8k3ZbQSl9TGgl99ZkZ3hKd8iL7sIe7AxGeiig==@lists.linux.dev X-Gm-Message-State: AOJu0Yz9IbwflLgIbZABAqhgeciswljoSXtM76bftQhbwLavRDg5XjSv zGRY6duUBaejUkzzbQeF3wQSUnyDACBNXzlcYXriyeqdX6//sDqnjWMg X-Gm-Gg: AR+sD11ZKr9CFnOAQa80z0sUBkz+kSrHXjDGpDHTRdVReYsmqRWeTpxSG2vrGln+lzO bV9SR3AYi30eLM/T4iC80clAQv1IS+11smVFDtPSvcpNJ9C1Fwfh5rxiKsh1tS0MgCZVyEMrtP6 xBLwdoqHKMmDUdnD9jxT1YNKU6FtxMC2eBsu/9iF60JoUwCBnWsZbSxO24Wz1QQBDwUfpZ3aOVv ZN4ibG3HF/Ivdb7vQSN6r7Q/jW2iqKUcUbissKj/ACVUeu8+2xsEf0DZZD0f9rvN+Yz3oEOQzTu LIXhV1Iwr+X+Xy4jVJF76jJ/SEwFF9il0rgJ9lXR/KBb3SRZC9kGWNfehHweh31bfRes8MuU1rs VXi0uk3+rRLGjSrEhlUdvU5yLI+cc8QKUfuAWiO2853VG14wYG6DWpxFHTBLrlLZTBP0G31icGU dznggCSIE17fU5rf1E8qCmbGyqKRgkCMrx4AfB2rbIM4V77R2mYdb3alycOYM32DWN0rgRJclI/ Sqmqw== X-Received: by 2002:a05:6300:141:b0:3c3:750f:3cf9 with SMTP id adf61e73a8af0-3cbd3ac3fbemr6024104637.11.1786187840297; Sat, 08 Aug 2026 04:17:20 -0700 (PDT) Received: from SGN-LDSENG.tasernet.com ([2405:4800:5cc3:11a:1ac0:4dff:fe8b:4a69]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315bebdf796sm17179976eec.22.2026.08.08.04.17.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 04:17:19 -0700 (PDT) From: Cong Nguyen To: Maxime Ripard , Mauro Carvalho Chehab , linux-media@vger.kernel.org Cc: Chen-Yu Tsai , Jernej Skrabec , Samuel Holland , Sakari Ailus , linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-kernel@vger.kernel.org, Cong Nguyen , stable@vger.kernel.org Subject: [PATCH v1 2/3] media: sun4i-csi: disable interrupts when stopping streaming Date: Sat, 8 Aug 2026 18:17:09 +0700 Message-Id: X-Mailer: git-send-email 2.25.1 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-sunxi@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-MORS-Enabled: yes X-MORS-DOMAIN: patchwork.local X-MORS-HOSTING: hosting172546 X-MORS-USER: hosting172546 X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= sun4i_csi_start_streaming() enables the frame-done interrupt in CSI_INT_EN_REG, but sun4i_csi_stop_streaming() only stops the capture engine (CSI_CPT_CTRL_REG) via sun4i_csi_capture_stop(). It never disables the interrupt source nor synchronizes with the handler. Capture stops at the end of the current frame, so a frame-done interrupt can still fire shortly after stop_streaming() returns. If userspace then closes the device, sun4i_csi_release() calls pm_runtime_put() and the CSI block is powered down (clocks gated, reset asserted). A delayed interrupt handler would then read/write CSI registers on the gated block, which can hang or crash the system. Clear CSI_INT_EN_REG and call synchronize_irq() in stop_streaming(), before returning the active buffers and freeing the scratch buffer, so no handler can run past this point. Store the IRQ number in struct sun4i_csi so it is available here. Fixes: 577bbf23b758 ("media: sunxi: Add A10 CSI driver") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4 Signed-off-by: Cong Nguyen --- drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.h | 1 + drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c | 11 +++++++++++ 2 files changed, 12 insertions(+) diff --git a/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.h b/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.h index 4e0c2df45d4d..51173faea871 100644 --- a/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.h +++ b/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.h @@ -112,6 +112,7 @@ struct sun4i_csi { const struct sun4i_csi_traits *traits; void __iomem *regs; + int irq; struct clk *bus_clk; struct clk *isp_clk; struct clk *ram_clk; diff --git a/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c b/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c index e911c7f7acc5..da697f39f2bc 100644 --- a/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c +++ b/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c @@ -354,6 +354,16 @@ static void sun4i_csi_stop_streaming(struct vb2_queue *vq) v4l2_subdev_call(csi->src_subdev, video, s_stream, 0); sun4i_csi_capture_stop(csi); + /* + * Disable the frame done interrupt and wait for the handler to + * finish. A frame may complete right as capture is stopped, so an + * interrupt can still be pending here; without this the handler could + * run after the device is powered down (pm_runtime_put() on release) + * and access registers on a gated block. + */ + writel(0, csi->regs + CSI_INT_EN_REG); + synchronize_irq(csi->irq); + /* Release all active buffers */ spin_lock_irqsave(&csi->qlock, flags); return_all_buffers(csi, VB2_BUF_STATE_ERROR); @@ -438,6 +448,7 @@ int sun4i_csi_dma_register(struct sun4i_csi *csi, int irq) dev_err(csi->dev, "Couldn't register our interrupt\n"); goto err_unregister_device; } + csi->irq = irq; return 0; From patchwork Sat Aug 8 11:17:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Cong Nguyen X-Patchwork-Id: 2953 Return-Path: X-Original-To: noreply@patchwork.local Delivered-To: noreply@patchwork.local Received: from sea.lore.kernel.org (sea.lore.kernel.org [172.234.253.10]) by mxe881.netcup.net (Postfix) with ESMTPS id 8C9F61C1930 for ; Sat, 8 Aug 2026 13:19:33 +0200 (CEST) Authentication-Results: mxe881; dkim=pass header.d=gmail.com; spf=pass (sender IP is 172.234.253.10) smtp.mailfrom=linux-sunxi+bounces-25079-noreply=patchwork.local@lists.linux.dev smtp.helo=sea.lore.kernel.org Received-SPF: pass (mxe881: domain of lists.linux.dev designates 172.234.253.10 as permitted sender) client-ip=172.234.253.10; envelope-from=linux-sunxi+bounces-25079-noreply=patchwork.local@lists.linux.dev; helo=sea.lore.kernel.org; Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sea.lore.kernel.org (Postfix) with ESMTP id 5849B3011C64 for ; Sat, 8 Aug 2026 11:17:40 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 9CEE33CB543; Sat, 8 Aug 2026 11:17:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="SM1ES7tQ" X-Original-To: linux-sunxi@lists.linux.dev Received: from mail-pl1-f178.google.com (mail-pl1-f178.google.com [209.85.214.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3B5CE37AA7D for ; Sat, 8 Aug 2026 11:17:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.178 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786187859; cv=none; b=hJ40E8Z5aGiVJTHczEXYL/jrr/X2/vKU5Zb2ZVoHS6iE35MeQEw6iSTzfzgNefsWavPnMfaMB4H1JjY9u/pFobLVqt+8ZV3ez8rjlZfYLTF1bvKSaEg+vP5nrF8SnEGlrGLZnZ/4J8qGYsu/lv1s1L01ciJXG75lXh8m6yKu4qY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786187859; c=relaxed/simple; bh=ON1kS1no0SPn9XlGXhFU53i+x3fCGvAcs6uB4rd1MZ8=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=U8b2/1ls/50ala7y1k1Uc1KBwTFHFh3F8787zd5tVTFcFj+p2Ou43tmD9Ef+zIWz/vb7Yfh6X9I/VKEI8nnu7g9jEelzBKMR1pW0r/uc9CrYzGD5z9LeK/+Jz0CNkSEgG5d3m3sCh6x5Ee5ZjPMhub0a2oKzPUg0umdNtdlf+5U= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=SM1ES7tQ; arc=none smtp.client-ip=209.85.214.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pl1-f178.google.com with SMTP id d9443c01a7336-2cc7e86e7aeso3855585ad.2 for ; Sat, 08 Aug 2026 04:17:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786187857; x=1786792657; darn=lists.linux.dev; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=3Vav1/IZDRyi5TmIe+ztFcmW7gzOkBU4RfYMZP3HSBU=; b=SM1ES7tQ6h0rfeNhsLqGZuaLNGuVPpXPbESvH7r3quQMGXym/RGL/WPBrUI4yDRnl2 9wVH3uoFsXwAwHIcP2PKtSo4cliVlU9N6so2VrGOxiZ4jpIdU/7UZ/+LIEeM0gVYEpss t3yVvnxURkic26+8bU6OQw22SjeMKproYIHYuJosVRbIkNQ54UktwXgNRdZt15soVNdD EDTGKR8RibOm8CKGAKijdFYBdeddlEAU5n4+UyL1zffWYPzXmre/2+F2jRyZ8HFSqdpP SxrGynT4VkyqZEijyJj7zLzu5i/GBz6nUxF5ES9xgbxlYDRnvqZm5KGCLDWwazrsJ2bP WGig== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786187857; x=1786792657; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=3Vav1/IZDRyi5TmIe+ztFcmW7gzOkBU4RfYMZP3HSBU=; b=NekH3giiG0MM3xlAtnJ0J5DR5WNZFraU0yL07SHIXvM6LMpE+o26glQ/LBPit+q6c8 Vy7oND31f0etBESB1ohSGScjzfyJHAiUX2cXwXH3rauHON/VzKxjtPZbY4rX6OIcBYaT WQQTHZXWIFVx/uW+WoxIJ8hzaRsFVv+MpdoZHsmEhvRoxW56H46H98laCtaAaS4fijaU z7Ri1W0Mzh1J/LaonuplAtSGWmM/wewiw1Z9nfy2mcpAvmxkfsP6B0yet5ZWKcna3NWq TK1R+rGMDj8Q7F5rwPOCj9O0XYeCcuuOo39zzAXsJI3wu5k/jSdvSXp94TnOzlq6pnaw nfIQ== X-Forwarded-Encrypted: i=1; AHgh+RoCAuSW7HRIciZiTSPrqXb6a3mfHnionvvZlW+J8Gb5pud2/DwCkN+wdBbw7U3potDUjNbKj3gXz3H4Hw==@lists.linux.dev X-Gm-Message-State: AOJu0Yy/VHC7YNcjE48fBknGV9TU/K9dbhn3zGzJsO06+LlTjdwQE3+e ghvzDdEdQbL07ldJIJ/l3Kvi/lBEOUdB3LC1yV74FK+8I0rqXMCBkQfI X-Gm-Gg: AR+sD13ES3gL6JF9hoTa1qx/Na2q945sIk52lbCJM5aOaltjSA0UXjn+zbLcC6jB3fA UlsP34y2ZmR3i9hEuuJfF3Bpd0/cF62gIzlYYxCNDKjudFey+chiW4vdEg6VD/LSqZNAFxI7R9X dufjGszQpd5Tg4zLvZ0Sp8kqbCKfMCJop65rYSSVYCcHW/h3TjbqRsQQuxhOUNkSRtlXl4jINnp 0gsWAj921I6eg8YFZjYT7N8abpQtJaTo2h3iK74uEo6d3BhBN4Pmb7rvAkPElp3NBu0gVDVeS9X J1vpAdqQ3R8hW2KS8u2PRjvwGg7EJNJABMdhWUlTWtQrMuy4QzwcydKF+5hpf5OyVNS7l5QwNUD M5CJqkB+b14eDn4TPQL0mV/W4uNZCydis+8epY3hSUQSA2JS8Ak37g8VWwgE1pU5mbNPLh0v3QT BkjMGxtMExaA/aytQJWA0f2uohc4MZJDjsOg/l1NpDPVhs77TMxo2K4MjmvErNYse7+MsRTRyxl m4+KA== X-Received: by 2002:a17:90b:448b:b0:38e:524:8797 with SMTP id 98e67ed59e1d1-3909d8c3b9cmr13238521a91.13.1786187857487; Sat, 08 Aug 2026 04:17:37 -0700 (PDT) Received: from SGN-LDSENG.tasernet.com ([2405:4800:5cc3:11a:1ac0:4dff:fe8b:4a69]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315bebde308sm18356313eec.20.2026.08.08.04.17.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 04:17:37 -0700 (PDT) From: Cong Nguyen To: Maxime Ripard , Mauro Carvalho Chehab , linux-media@vger.kernel.org Cc: Chen-Yu Tsai , Jernej Skrabec , Samuel Holland , Sakari Ailus , linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-kernel@vger.kernel.org, Cong Nguyen , stable@vger.kernel.org Subject: [PATCH v1 3/3] media: sun4i-csi: add notifier unbind callback to drop the source subdev Date: Sat, 8 Aug 2026 18:17:28 +0700 Message-Id: <61d4901af20a4d2d0f9484328c173bbdfc52ec05.1786184456.git.congnt264@gmail.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-sunxi@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-MORS-Enabled: yes X-MORS-DOMAIN: patchwork.local X-MORS-HOSTING: hosting172546 X-MORS-USER: hosting172546 X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= sun4i_csi_notify_ops only implements .bound and .complete. When the remote sensor's subdevice goes away (e.g. its module is unloaded), the V4L2 async core unbinds and frees it, but the driver keeps the stale pointer in csi->src_subdev and leaves the video node registered. A subsequent VIDIOC_STREAMON reaches sun4i_csi_start_streaming(), which calls v4l2_subdev_call(csi->src_subdev, video, s_stream, 1) on the freed subdev, resulting in a use-after-free. Add an .unbind callback that unregisters the video device so userspace can no longer start streaming, and clears csi->src_subdev. Unregistering the already-unregistered video device again in sun4i_csi_remove() is harmless (vb2_video_unregister_device() is a no-op when it is not registered). Fixes: 577bbf23b758 ("media: sunxi: Add A10 CSI driver") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4 Signed-off-by: Cong Nguyen --- .../media/platform/sunxi/sun4i-csi/sun4i_csi.c | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.c b/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.c index a8711336a754..6610ada1c06d 100644 --- a/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.c +++ b/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.c @@ -122,8 +122,25 @@ static int sun4i_csi_notify_complete(struct v4l2_async_notifier *notifier) return ret; } +static void sun4i_csi_notify_unbind(struct v4l2_async_notifier *notifier, + struct v4l2_subdev *subdev, + struct v4l2_async_connection *asd) +{ + struct sun4i_csi *csi = container_of(notifier, struct sun4i_csi, + notifier); + + /* + * The remote subdev is being freed. Tear down the video node so + * userspace can no longer reach sun4i_csi_start_streaming() and + * dereference the now dangling source subdev, and drop the pointer. + */ + vb2_video_unregister_device(&csi->vdev); + csi->src_subdev = NULL; +} + static const struct v4l2_async_notifier_operations sun4i_csi_notify_ops = { .bound = sun4i_csi_notify_bound, + .unbind = sun4i_csi_notify_unbind, .complete = sun4i_csi_notify_complete, };